diff --git a/reference/PAN-OS/addressed/10.2.10-h30.html b/reference/PAN-OS/addressed/10.2.10-h30.html new file mode 100644 index 0000000..e4ce011 --- /dev/null +++ b/reference/PAN-OS/addressed/10.2.10-h30.html @@ -0,0 +1,61 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-301222
+ |
+
+
+ Fixed an issue where DNS Security logs incorrectly displayed a
+ sinkhole action for benign DNS categories due to the firewall saving
+ the drop or sinkhole action in session flags without discarding the
+ session.
+
+ |
+
|
+ PAN-291653
+ |
+
+
+ Fixed an issue where the GlobalProtect host ID field was
+ intermittently blank in traffic logs on Prisma Access, even when the
+ user was connected and had the correct host ID information. This
+ occurred when the IP address to host ID entry expired and the entry
+ was re-inserted without the dataplane flag being set.
+
+ |
+
|
+ PAN-195264
+ |
+
+
+ Fixed an issue where the login lifetime countdown timer reset when
+ using an authentication override cookie to log in to the gateway.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-312703
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-306502
+ |
+
+
+ Fixed an issue where TLS connection failure occurred when traffic was
+ over TLS1.2 or below, header insertion was enabled on the firewall,
+ send TLS handshake to CTD was
+ enabled, and traffic hit a decryption policy rule configured with the
+ no-decrypt action.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-316911
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-312706
+ |
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking
+ a NULL-pointer sanity check.
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ (Panorama managed firewalls only) Fixed an
+ issue where the firewall intermittently failed to maintain active log
+ forwarding streams to Strata Logging Service (SLS) even when duplicate
+ logging and enhanced application logging were enabled.
+
+ |
+
|
+ PAN-307795
+ |
+
+
+ Fixed an issue where Panorama incorrectly generated system logs
+ indicating a lost connection to its peer after an upgrade even when
+ High Availability was not configured.
+
+ |
+
|
+ PAN-307597
+ |
+
+
+ Fixed an issue where BGP peering sessions between a hub firewall and a
+ satellite firewall over GlobalProtect LSVPN failed to connect.
+
+ |
+
|
+ PAN-305415
+ |
+
+
+ Fixed an issue where commits caused high dataplane CPU utilization and
+ briefly increased Packet Descriptors, which disrupted traffic.
+
+ |
+
|
+ PAN-304756
+ |
+
+
+ Fixed an issue on Panorama where, after you disabled the shared
+ optimization feature, a full configuration push to multi-vsys devices
+ caused a validation error.
+
+ |
+
|
+ PAN-303051
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the
+ reportd
+ process due to retaining memory that was temporarily used for report
+ generation instead of releasing the memory for reuse, which resulted
+ in continuous accumulation and memory exhaustion.
+
+ |
+
|
+ PAN-301409
+ |
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a
+ managed device when device tags were added or modified on the policy
+ rules. The selective push would fail with the error message
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-300671
+ |
+
+
+ Fixed an issue where traffic reports that were generated with
+ destination/source and destination/source hostnames were not displayed
+ in IPv4 format.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade
+ due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ which caused the process to take an extended amount of time.
+
+ |
+
|
+ PAN-295470
+ |
+
+
+ Fixed an issue on the firewall where the
+ useridd
+ process continuously increased its memory consumption, which resulted
+ in an OOM condition that caused the firewall to restart.
+
+ |
+
|
+ PAN-291067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process periodically exceeded its virtual memory limit and restarted,
+ which led to intermittent outages.
+
+ |
+
|
+ PAN-291009
+ |
+
+
+ Fixed an issue where, after a web server returned a 401 or 403 error,
+ the firewall was unable to decrypt HTTP/2 traffic, and the firewall
+ rejected all subsequent streams from the client.
+
+ |
+
|
+ PAN-289249
+ |
+
+
+ Fixed an issue where a memory leak occurred on the
+ reportd
+ process when a WildFire update was initiated while device telemetry
+ data collection was in progress. This resulted in an OOM condition.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ Fixed a cumulative memory leak in the
+ devsrvr
+ process that occurred whenever the CLI command
+ show running application statistics
+ was issued. This memory leak would gradually consume system memory and
+ produce an OOM condition, causing the firewall to reboot.
+
+ |
+
|
+ PAN-280196
+ |
+
+
+ Fixed an issue in Prisma Access environments where the firewall
+ matched a HIP object but not on the HIP profile that contained the
+ object.
+
+ |
+
|
+ PAN-279364
+ |
+
+
+ (VM-Series firewalls with multiple NICs only)
+ Fixed an issue were the queue count in the task dump displayed an
+ incorrect number of queues for SR-IOV interfaces due to the queue
+ mapping logic incorrectly using a non-multi-NIC function.
+
+ |
+
|
+ PAN-274742
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the task-queue dump CLI command
+ returned incorrect information in multi-nic mode.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-252809
+ |
+
+
+ Fixed an issue where a single PIM neighbor was sending 0.0.0.0 as its
+ address, which occurred because an improvement in PIM neighbor address
+ selection did not correctly account for configurations with a single
+ IP address.
+
+ |
+
|
+ PAN-242952
+ |
+
+
+ Fixed an issue where high SSL traffic depleted flex memory, which
+ prevented the firewall from revalidating SSLVPN client CAs during
+ configuration pushes.
+
+ |
+
|
+ PAN-230748
+ |
+
+
+ Fixed an issue where the firewall displayed the current time as the
+ expiration date for an imported certificate in the CLI output instead
+ of the correct expiry time due to an improper use of an OpenSSL
+ library function.
+
+ |
+
|
+ PAN-202911
+ |
+
+
+ Fixed an issue where a satellite tunnel was not established after
+ turning on satellite firewalls.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-303559
+ |
+
+
+ Fixed an issue where, after manuallly creating a device telemetry
+ bundle, the
+ hour_cli_output.txt file within
+ the bundle had a file size of 0 bytes. This occurred when checking the
+ bundle content after enabling device telemetry and setting the device
+ telemetry upload endpoint.
+
+ |
+
|
+ PAN-301018
+ |
+
+
+ Fixed an issue on Panorama where API queries for correlated category
+ logs incorrectly returned a count of 0.
+
+ |
+
|
+ PAN-300055
+ |
+
+
+ Fixed an issue where the firewall experienced high disk utilization in
+ the /opt/pancfg/mgmt/content-preview directory due to older content
+ data not being automatically removed when an error occurred during the
+ process.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release,
+ the Visible Virtual System field referenced the vsys name instead of
+ the vsys ID, which caused inter-vsys routing to fail. This occurred
+ when a vsys display name matched one of the vsys IDs. If you're using
+ a multivsys environment, you must upgrade your firewalls to a fixed
+ PAN-OS version. The best practice is to upgrade both the firewalls and
+ Panorama to a fixed PAN-OS version.
+
+
|
+
|
+ PAN-297708
+ |
+
+
+ Fixed an issue where a long-lived session with many Machine Learning
+ (ML) model triggers caused a memory leak of feature states associated
+ with the ML model runs. This resulted in Spyware_State failure
+ increases, allocation max outs, and impaired policy matching.
+
+ |
+
|
+ PAN-297609
+ |
+
+
+ Fixed an issue where the the CLI command
+ debug user-id refresh user-id agent all
+ failed with the error message
+ Invalid agent name. Agent name should be 1 to 31 characters
+ long.
+
+ |
+
|
+ PAN-297261
+ |
+
+
+ Fixed an issue where the proxy-protocol debug level was set to
+ verbose on Prisma Access
+ instances, even when it was not explicitly configured, which caused
+ excessive logging by the
+ pan_task
+ process.
+
+ |
+
|
+ PAN-295095
+ |
+
+
+ Fixed an issue where, when you used a syslog forwarding profile with
+ the CEF format, an additional string was appended to the end of the
+ log message when viewing the log entry from the Universal Forwarder
+ directory.
+
+ |
+
|
+ PAN-295049
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to memory allocation errors during
+ Redis communication.
+
+ |
+
|
+ PAN-294893
+ |
+
+
+ Fixed an issue where firewalls with the
+ Send handshake messages to CTD for inspection
+ setting enabled caused incorrect security policy rules to be matched.
+ Specifically, traffic not identified as openai-base or openai-chatgpt
+ applications was incorrectly matched by the
+ ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
+ response page for blocked URLs was not displayed.
+
+ |
+
|
+ PAN-292447
+ |
+
+
+ Fixed an issue where Panorama did not display data in the
+ Feature Adoption tab in Strata Cloud
+ Manager due to the system creating and deleting a CLI user for each
+ interval instead of reusing a permanent CLI user for telemetry.
+
+ |
+
|
+ PAN-291172
+ |
+
+
+ Fixed an issue where administrators were unable to gather path
+ monitoring failure information when troubleshooting high dataplane CPU
+ utilization.
+
+ |
+
|
+ PAN-290665
+ |
+
+
+ Fixed an issue with firewalls enabled with Security profiles where
+ certain traffic conditions caused high dataplane CPU utilization and
+ packet buffer exhaustion, which caused LACP flapping conditions.
+
+ |
+
|
+ PAN-289067
+ |
+
+
+ Fixed an issue where, after upgrading Panorama in a High Availability
+ (HA) pair, the configuration logs stopped synchronizing from the
+ primary Panorama to the secondary Panorama. This issue occurred
+ because the log forwarding flag was permanently disabled due to the
+ connection state not being active when the
+ log-fwd-ctrl message was
+ received.
+
+ |
+
|
+ PAN-288097
+ |
+
+
+ Fixed an issue where on the firewall where the
+ routed
+ process stopped responding after changing the MTU or any link state
+ parameters when OSPF and PIM were enabled on the same interface.
+
+ |
+
|
+ PAN-287387
+ |
+
+
+ Fixed an issue on Panorama where API jobs failed with the error
+ message
+ Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a
+ large number of address objects in a single set call.
+
+ |
+
|
+ PAN-285208
+ |
+
+
+ Fixed an issue where the firewall did not automatically recover after
+ a machine check exception (MCE) occurred.
+
+ |
+
|
+ PAN-283237
+ |
+
+
+ Fixed an issue where traffic logs incorrectly displayed the action as
+ allow for traffic matching a
+ Security policy rule configured with the action set to
+ deny. This issue occurred due to the
+ child session being used for policy rule lookup when a configuration
+ update triggered a rematch if the FTP-data application was not in the
+ rule.
+
+ |
+
|
+ PAN-281588
+ |
+
+
+ Fixed an issue where packet buffer depletion occurred due to the a
+ high number of
+ tcp_pkt_queued packets when Jumbo
+ was enabled.
+
+ |
+
|
+ PAN-266843
+ |
+
+
+ Fixed an issue on airgapped firewalls where cloud connection errors
+ flooded the system logs.
+
+ |
+
|
+ PAN-262353
+ |
+
+
+ Fixed an issue where, when Panorama was upgraded to PAN-OS 10.2.10,
+ and log collectors were on PAN-OS 10.2.9-h1, logs from a log collector
+ group were not viewable on a Panorama.
+
+ |
+
|
+ PAN-237349
+ |
+
+
+ Fixed an issue where URLs with over 965 characters were unable to be
+ logged in the URL filtering log.
+
+ |
+
|
+ PAN-233542
+ |
+
+
+ Fixed an issue where the firewall did not display the source address
+ due to an uninitialized scalar variable.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ PAN-323243
+ |
+
+
+ Fixed an issue where a
+ configd
+ crash occurred when the
+ Policies > Security view was
+ updated or refreshed in the web interface.
+
+ |
+
|
+ PAN-317215
+ |
+
+
+ (VM-Series firewalls on ESXi with Intel E810 NICs using PCI
+ passthrough) Fixed an issue where the
+ brdagent
+ process became unresponsive during data port initialization, which
+ resulted in system instability, interface outages, HA split-brain
+ conditions, and unexpected reboots during failover.
+
+ |
+
|
+ PAN-317155
+ |
+
+
+ Fixed an issue where the link status of log port 1 and log port 2 were
+ unable to be monitored via SNMP due to the OIDs for the individual
+ ports not being available.
+
+ |
+
|
+ PAN-314875
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ firewall logs were not visible in the Strata Logging Service even
+ though cloud logging was enabled and the firewall was successfully
+ forwarding logs.
+
+ |
+
|
+ PAN-314126
+ |
+
+
+ Fixed an issue where session rematch did not properly apply updated
+ Security policy rules to existing traffic flows after committing
+ changes, which caused traffic to still be allowed when a new Security
+ policy was set to Deny.
+
+ |
+
|
+ PAN-311166
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly to the
+ all_task_1
+ process repeatedly restarting.
+
+ |
+
|
+ PAN-310472
+ |
+
+
+ Fixed an issue on the web interface where checkboxes for
+ default information originate and
+ ABR in OSPF NSSA configurations were automatically enabled which
+ resulted in unexpected configuration changes.
+
+ |
+
|
+ PAN-308377
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue where the firewall reached 100% disk utilization due to
+ the
+ logrcvr
+ process repeatedly restarting and dumping core files due to a blocked
+ hints processing thread, which caused a failover.
+
+ |
+
|
+ PAN-307714
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ insufficient i-node space was available on the sysroot0 partition.
+
+ |
+
|
+ PAN-302196
+ |
+
+
+ Fixed an issue where the dataplane stopped responding when cleaning up
+ expired sessions currently in Advanced Threat Prevention hold mode.
+
+ |
+
|
+ PAN-277629
+ |
+
+
+ Fixed an issue where the firewall did not match the correct policy for
+ SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
+ 10.2.9-h1 to PAN-OS 11.2.3.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ PAN-323243
+ |
+
+
+ Fixed an issue where a
+ configd
+ crash occurred when the
+ Policies > Security view was
+ updated or refreshed in the web interface.
+
+ |
+
|
+ PAN-318567
+ |
+
+
+ Fixed an issue where the OpenConfig plugin stopped working after a
+ configuration update.
+
+ |
+
|
+ PAN-317583
+ |
+
+
+ Fixed an issue with intermittent ICMP ping drops and packet loss in
+ traffic flows between a hub and branch after upgrading to an affected
+ PAN-OS release due to incorrect SD-WAN path monitor state.
+
+ |
+
|
+ PAN-317466
+ |
+
+
+ Fixed an issue where SIP sessions stopped progressing after the
+ firewall received fragmented packets, fragmented at header field.
+
+ |
+
|
+ PAN-317215
+ |
+
+
+ (VM-Series firewalls on ESXi with Intel E810 NICs using PCI
+ passthrough) Fixed an issue where the
+ brdagent
+ process became unresponsive during data port initialization, which
+ resulted in system instability, interface outages, HA split-brain
+ conditions, and unexpected reboots during failover.
+
+ |
+
|
+ PAN-317177
+ |
+
+
+ Fixed an issue on firewalls in DHCP Client mode where, after upgrading
+ to an affected release, the SNMP process unexpectedly restarted after
+ a commit, which led to false interface flap notifications on SNMP
+ managers.
+
+ |
+
|
+ PAN-317155
+ |
+
+
+ Fixed an issue where the link status of log port 1 and log port 2 were
+ unable to be monitored via SNMP due to the OIDs for the individual
+ ports not being available.
+
+ |
+
|
+ PAN-316631
+ |
+
+
+ Fixed an issue BGP sessions experienced short disruptions across all
+ peers, interfaces, and slots when a multicast event persisted longer
+ than the NGP negotiated hold timers.
+
+ |
+
|
+ PAN-314875
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ firewall logs were not visible in the Strata Logging Service even
+ though cloud logging was enabled and the firewall was successfully
+ forwarding logs.
+
+ |
+
|
+ PAN-314435
+ |
+
+
+ Fixed an issue on the Panorama web interface where custom application
+ tags for cloud applications were not consistently displayed in the
+ Application Filter or application details even though the tags were
+ configured via CLI and successfully enforced traffic blocking policy
+ rules.
+
+ |
+
|
+ PAN-314126
+ |
+
+
+ Fixed an issue where session rematch did not properly apply updated
+ Security policy rules to existing traffic flows after committing
+ changes, which caused traffic to still be allowed when a new Security
+ policy was set to Deny.
+
+ |
+
|
+ PAN-313193
+ |
+
+
+ (Firewalls in Layer 2 mode only) Fixed an issue
+ where the new sessions were not able to be established due to the
+ firewall intermittently dropping valid MAC address entries for
+ specific VLANs when a manual switchover sent a high volume of traffic
+ to the firewall.
+
+ |
+
|
+ PAN-311248
+ |
+
+
+ Fixed an issue where the ABR failed to translate and advertise the
+ default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF
+ backbone area as a Type-5 LSA.
+
+ |
+
|
+ PAN-310472
+ |
+
+
+ Fixed an issue on the web interface where checkboxes for
+ default information originate and
+ ABR in OSPF NSSA configurations were automatically enabled which
+ resulted in unexpected configuration changes.
+
+ |
+
|
+ PAN-308377
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue where the firewall reached 100% disk utilization due to
+ the
+ logrcvr
+ process repeatedly restarting and dumping core files due to a blocked
+ hints processing thread, which caused a failover.
+
+ |
+
|
+ PAN-307714
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ insufficient i-node space was available on the sysroot0 partition.
+
+ |
+
|
+ PAN-295728
+ |
+
+
+ Fixed an issue where configuring an OSPFv2 NSSA area range caused
+ OSPF-learned routes to become unreachable due to the incorrect
+ installation of a discard route when the NSSA range prefix matched an
+ existing OSPF route.
+
+ |
+
|
+ PAN-295309
+ |
+
+
+ Fixed an issue where OSPF session using MD5 authentication experienced
+ intermittent flapping due to out-of-order packet processing.
+
+ |
+
|
+ PAN-277629
+ |
+
+
+ Fixed an issue where the firewall did not match the correct policy for
+ SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS
+ 10.2.9-h1 to PAN-OS 11.2.3.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ PAN-265399
+ |
+
+
+ Fixed an issue where DNS queries for uppercase internal domain (SRV
+ record) timed out when DNS Security was enabled.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ PAN-323243
+ |
+
+
+ Fixed an issue where a
+ configd
+ crash occurred when the
+ Policies > Security view was
+ updated or refreshed in the web interface.
+
+ |
+
|
+ PAN-322281
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the HA 2 interface did not come up on the passive
+ firewall, which resulted in the firewall being unable to join the HA
+ pair.
+
+ |
+
|
+ PAN-314126
+ |
+
+
+ Fixed an issue where session rematch did not properly apply updated
+ Security policy rules to existing traffic flows after committing
+ changes, which caused traffic to still be allowed when a new Security
+ policy was set to Deny.
+
+ |
+
|
+ PAN-311166
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly to the
+ all_task_1
+ process repeatedly restarting.
+
+ |
+
|
+ PAN-308377
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue where the firewall reached 100% disk utilization due to
+ the
+ logrcvr
+ process repeatedly restarting and dumping core files due to a blocked
+ hints processing thread, which caused a failover.
+
+ |
+
|
+ PAN-307901
+ |
+
+
+ Fixed an issue where a leak in decryption counters caused resource
+ exhaustion, which led to a GlobalProtect service outage.
+
+ |
+
|
+ PAN-307714
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ insufficient i-node space was available on the sysroot0 partition.
+
+ |
+
|
+ PAN-302196
+ |
+
+
+ Fixed an issue where the dataplane stopped responding when cleaning up
+ expired sessions currently in Advanced Threat Prevention hold mode.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ This hotfix includes performance and bug fixes.
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ PAN-317215
+ |
+
+
+ (VM-Series firewalls on ESXi with Intel E810 NICs using PCI
+ passthrough) Fixed an issue where the
+ brdagent
+ process became unresponsive during data port initialization, which
+ resulted in system instability, interface outages, HA split-brain
+ conditions, and unexpected reboots during failover.
+
+ |
+
|
+ PAN-315919
+ |
+
+
+ Fixed an issue where GlobalProtect pre-logon tunnel session was not
+ cleared even after the user was logged in. With this fix, the session
+ is cleared after the session timeout expires.
+
+ |
+
|
+ PAN-313849
+ |
+
+
+ Fixed an issue on Panorama where the
+ logd
+ process exited unexpectedly when handling syslog forwarding.
+
+ |
+
|
+ PAN-311192
+ |
+
+
+ Fixed an issue where the
+ device-telemetry collect-now
+ process became unresponsive when the process was initiated multiple
+ times with other processes running concurrently, which prevented
+ subsequent telemetry collection.
+
+ |
+
|
+ PAN-308377
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue where the firewall reached 100% disk utilization due to
+ the
+ logrcvr
+ process repeatedly restarting and dumping core files due to a blocked
+ hints processing thread, which caused a failover.
+
+ |
+
|
+ PAN-306356
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process on a firewall stopped responding due to a document node being
+ unexpectedly freed.
+
+ |
+
|
+ PAN-303663
+ |
+
+
+ Fixed an issue on the firewall where SolarWinds monitoring systems
+ reported 100% usage for Slot1 Data Processor-0 Hardware Packet Buffers
+ due to an inaccurate reported packet buffer.
+
+ |
+
|
+ PAN-295806
+ |
+
+
+ Fixed an issue where memory leaks on the
+ configd
+ process occurred due to a hash insert operation failing during
+ connection management and SSL connections.
+
+ |
+
|
+ PAN-288175
+ |
+
+
+ Addressed a stack buffer overflow memory leak under plugin management
+ code path.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-314201
+
+ This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues
+
+ |
+
+
+ On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party
+ peer devices may experience intermittent traffic loss during rekey
+ operations. When a new Security Association (SA) forms before the old
+ SA expires, traffic may stop flowing until the older SA naturally
+ expires or you manually clear it. During this time, the output of show
+ vpn ipsec-sa may show two SAs for the same proxy ID. This issue
+ primarily affects tunnels to third-party peer devices and does not
+ occur with Palo Alto Networks to Palo Alto Networks tunnels.
+
+
+ Workaround: Manually clear the affected Security
+ Association using the command
+ clear vpn ipsec-sa tunnel <tunnel-name>
+ to restore connectivity.
+
+ |
+
|
+ PAN-313623
+ |
+
+
+ On firewalls with TPM (Trusted Platform Module) support, device
+ certificate renewals may fail due to a disk partition being full. This
+ latter occurs because temporary files aren't being deleted during
+ device certificate status checks.
+
+ |
+
|
+ PAN-312706
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ Firewalls may restart unexpectedly due to an internal error in content
+ inspection processing. This issue can occur when the firewall is
+ performing antivirus scanning, URL filtering, or WildFire analysis.
+
+ |
+
|
+ PAN-309604
+ |
+
+
+ (PA-5500 series only) In some rare cases, the
+ front panel PSU status LED might show amber, even when the LEDs on the
+ PSU show green.
+
+ |
+
|
+ PAN-309602
+ |
+
+
+ (PA-5500 series only) When the firewall is
+ initially powered on, the FAN-0 LED does not turn on. The fan
+ functions correctly, but the LED doesn't reflect the status.
+
+
+ Workaround: Remove and reinsert the fan to turn on
+ the LED.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+
+ This issue is now resolved. See PAN-OS 12.1.6 Addressed Issues.
+
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the
+ log-receiver
+ process temporarily resolves the issue, but the streams become
+ inactive again after approximately 1-2 hours. This intermittent
+ inactivity results in log loss.
+
+ |
+
|
+ PAN-307702
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ When LACP pre-negotiation is enabled on firewalls in HA
+ configurations, traffic passing through aggregate Ethernet (AE)
+ interfaces may be interrupted for several minutes during HA failovers.
+ This occurs because the suspended (formerly active) firewall continues
+ to forward packets for active sessions even after the failover
+ completes, causing MAC address flapping on neighboring switches.
+
+ |
+
|
+ PAN-305880
+ |
+
+
+ (PA-7500 firewalls only) Intermittent internet
+ connectivity failures on the logging interface might trigger a
+ dataplane disconnect from Strata Logging Service (SLS) and WildFire
+ cloud.
+
+ |
+
|
+ PAN-305301
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+
+ Workaround: Select
+ Network > GlobalProtect > Gateways >
+ <gateway-config> > Agent > <agent-config> >
+ Connection Settings
+ and change the value of both
+ Notify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
+ to 0.
+
+ |
+
|
+ PAN-304718
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ When using GlobalProtect Clientless VPN, the firewall may restart
+ unexpectedly, causing routing protocol (OSPF and BGP) outages. This
+ issue occurs during web content processing for clientless VPN
+ sessions.
+
+
+ Workaround: To prevent this issue until you can
+ upgrade to a fixed release, disable clientless VPN in your
+ GlobalProtect portal configuration.
+
+ |
+
|
+ PAN-304576
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-303663
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ After upgrading to an affected release, SNMP monitoring systems such
+ as SolarWinds may report 100% usage for hardware packet buffers on
+ PA-3400 Series and PA-5450 firewalls, even when the firewall is idle
+ and packet buffer utilization is normal. The packet buffer utilization
+ oid is fixed to not show incorrect values.
+
+ |
+
|
+ PAN-300850
+ |
+
+
+ Manual scheduling of cloud verdicts is required if a new host in an
+ Host Compliance Service-enabled environment has a refresh event entry
+ without a corresponding update event entry.
+
+ |
+
|
+ PAN-300809
+ |
+
+
+ Host Compliance Service connectivity will not work if it is connected
+ with management IP which is configured with DHCP mode.
+
+ |
+
|
+ PAN-300677
+ |
+
+
+ Panorama cannot display Threat log entries (Monitor > Logs > Threat) when the managed log collector is running a lower PAN-OS release
+ than Panorama.
+
+
+ Workaround: Upgrade the log collectors to the same version as
+ Panorama.
+
+ |
+
|
+ PAN-300671
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ Traffic reports that display destination/source IP addresses or
+ destination/source hostnames may incorrectly show IPv4 addresses in
+ IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both
+ custom reports and scheduled reports, including PDF exports.
+
+ |
+
|
+ PAN-300627
+ |
+
+
+ AutoCommit fails when the Traffic Object is used on AI Runtime
+ Security, which consequently impacts the workloads that utilize
+ overlapping subnets.
+
+ |
+
|
+ PAN-300483
+ |
+
+
+ (PA-7500 firewall only) Enabling FIPS-CC mode
+ causes the firewall to go into maintenance mode.
+
+
+ Workaround: After the firewall goes into
+ maintenance mode, perform an additional reboot. The firewall will
+ successfully start up in FIPS-CC mode.
+
+ |
+
|
+ PAN-300467
+ |
+
+
+ WildFire WF-500 appliances running PAN-OS 10.x or PAN-OS 11.x cannot
+ be managed by Panorama running PAN-OS 12.1.2 due to connectivity
+ issues.
+
+
+ Workaround: Upgrade your WildFire appliances to
+ PAN-OS 12.1.2 or later.
+
+ |
+
|
+ PAN-300407
+ |
+
+
+ The Release Note URL column in the Panorama > Plugins page is
+ empty.
+
+
+ Release Notes for the plugins are available in the
+ plugins release notes
+ or in their individual product release notes.
+
+ |
+
|
+ PAN-300230
+ |
+
+
+ (NGFW Cluster) In an NGFW cluster, your pings
+ to the HSCI-B link might fail, even when the link indicates it is up.
+ In the event that the HSCI-A link is brought down or unplugged, the
+ cluster node will transition to failed state, avoiding split brain as
+ both HSCI links are down in this case.
+
+
+ Workaround: Reboot the cluster node to resolve the
+ HSCI-B ping issue.
+
+ |
+
|
+ PAN-300192
+ |
+
+
+ If the Host Compliance Service is configured with a service route
+ pointing to an unreachable IP address, the
+ gp_broker process may stop
+ working when you enable-disable the Host Compliance Service.
+
+ |
+
|
+ PAN-300114
+ |
+
+
+ VM entered maintenance mode during a downgrade from version 12.1.2 to
+ 11.2.7, when executed through the CLI.
+
+
+ Workaround: Download and install the required
+ version of PAN-OS through the UI instead of the CLI.
+
+ |
+
|
+ PAN-300069
+ |
+
+
+ (PA-410 firewall only) Loading a saved config
+ file can take up to 5 minutes.
+
+ |
+
|
+ PAN-300053
+ |
+
+
+ When you use the CLI command
+ request system fqdn refresh to
+ trigger another IP address resolution of configured FQDN entries, the
+ firewall might get into an error state where the DNS Proxy cache
+ received and stored a new IP address for a particular FQDN entry via
+ this command. However, the Device-Server (and the Security rule) still
+ have the old IP address for that FQDN entry.
+
+
+ Workaround: Avoid using the CLI command:
+ request system fqdn refresh. Use the
+ following command instead (for a particular domain-name or an entire
+ list):
+ clear dns-proxy cache all domain-name <domain_name>. To correct the error state where the DNS Proxy cache and
+ Device-Server and Security rule are already storing different IP
+ addresses, use the following CLI command:
+ debug device-server dump fqdn type resync vsys <vsys_name>
+ fqdn-name <domain_name>
+
+ |
+
|
+ PAN-300025
+ |
+
+
+ If Azure hotplug events occur, the firewall may experience a
+ brdagent crash and data interfaces
+ may transition to an unknown state, leading to traffic disruption.
+
+
+ Workaround: Reboot the VM if the
+ brdagent crash does not trigger a
+ device reboot.
+
+ |
+
|
+ PAN-299562
+ |
+
+
+ SSL proxy sessions fail when clients send a Client Hello with TLSv1.2
+ and TLSv1.3, and exclusively prefer the secp192 elliptic curve.
+
+
+ Workaround: To address this, configure a
+ decryption profile to use TLSv1.2 as the maximum supported TLS
+ version. Then, apply this profile to the decryption policy rules for
+ the affected clients and servers. This enables the client to modify
+ its preferred curves, facilitating successful session establishment.
+
+ |
+
| PAN-299387 | +
+
+ (NGFW Cluster) When an NGFW cluster has only
+ one firewall node present and powered up, that node is stuck in
+ UNKNOWN state after you reboot it and it comes back up. The issue
+ occurs in two scenarios:
+
+
+ The expected behavior is that if no peer device is available (at a
+ port autonegotiation or link level for HSCI-A or HSCI-B), then a
+ cluster device should go to INITIAL state, followed by ONLINE state
+ (and not remain in UNKNOWN state).
+
+
+ Workaround: To avoid this issue, connect the
+ HSCI-A to HSCI-B in loopback to create a link partner.
+
+ |
+
| PAN-299229 | +
+
+ On PA-5400 Series and PA-7500 Series firewalls, if you run certain
+ types of CLI commands during or shortly after a commit, the commands
+ will time out. The types of CLI commands impacted by this issue are
+ IoT, Cloud-User-ID, and App-ID Cloud Engine CLI commands.
+
+
+ Workaround: Don't execute IoT, Cloud-User-ID, or
+ App-ID Cloud Engine CLI commands during or shortly after a commit on a
+ PA-5400 Series or PA-7500 Series firewall.
+
+ |
+
| PAN-299170 | +
+
+ The remediation link included in the generated PDF of an upgrade check
+ report might be pruned due to a text length limitation of the export
+ function. The link remains fully functional and works correctly on the
+ Panorama web interface.
+
+ |
+
| PAN-299114 | +
+
+ After you enable the
+ Enable Duplicate Logging (Cloud and On-Premise) setting on a firewall, clicking
+ Status for Cloud Logging, does not
+ display the logging service connection status.
+
+ |
+
| PAN-298540 | +
+
+ (PA-5500 Series firewalls only) The
+ Monitor tab in the Web Interface
+ does not display a pop-up to indicate that high-speed log forwarding
+ is enabled and that logs are only viewable from Panorama.
+
+ |
+
| PAN-298083 | +
+
+ After you change the system mode on an M-700 appliance from Panorama
+ mode to PAN-DB private cloud mode, the
+ snmpd process fails to work.
+
+ |
+
| PAN-298047 | +
+
+ In an AI Runtime Security environment, the Azure Container outbound
+ traffic does not seem to be functional and the egress traffic is being
+ misdirected to an incorrect cluster node port.
+
+ |
+
| PAN-297772 | +
+
+ When an Intel e810 NIC is configured in SR-IOV mode, sharing Virtual
+ Functions (VFs) among multiple HSF cluster nodes and subsequently
+ rebooting a cluster node while traffic is active may result in traffic
+ disruption on other HSF cluster nodes utilizing the same NIC. It is
+ recommended to refrain from sharing Intel e810 VFs across cluster
+ nodes and to allocate one VF per Intel e810 PF.
+
+ |
+
|
+ PAN-297610
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the `fsck`
+ command scanning drive partitions in parallel with the root partition,
+ causing the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297114
+ |
+
+
+ After successfully generating a health check report for managed
+ firewalls from Panorama, the progress bar does not appear and the
+ latest health check reports are not displayed (Panorama > Device Deployment > Upgrade Check).
+
+
+ Workaround: Manually refresh the page to see the
+ latest reports.
+
+ |
+
|
+
+ PAN-295803This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294687
+ |
+
+
+ (NGFW Clusters) In an NGFW cluster, the leader
+ can't retrieve the HIP Report from Panorama, nor synchronize it to the
+ non-leader nodes. Unlike HA Active/Passive mode, both leader and
+ non-leader nodes receive traffic in cluster mode. If the relevant HIP
+ Report is missing, policies involving HIP may not work properly. The
+ expected behavior is that when a non-leader node receives related
+ traffic, it should request the corresponding HIP Report from the
+ leader.
+
+ |
+
|
+ PAN-293754
+ |
+
+
+ (NGFW Clusters) Firewalls in an NGFW cluster
+ indicate they are in ONLINE state even though their configurations are
+ different (they aren't synchronized).
+
+
+ Workaround: Push the configuration from Panorama
+ to all cluster members at the same time; don't push to an individual
+ firewall. If a cluster member isn't connected to Panorama during the
+ push, the push will fail to the disconnected firewall, but will
+ succeed to all connected firewalls.
+
+ |
+
|
+ PAN-293718
+ |
+
+
+ When high speed logging is enabled on a PA-5560 device, the expected
+ warning message is not displayed on the web interface. This prevents
+ administrators from being notified that logs can only be viewed from
+ Panorama.
+
+ |
+
|
+ PAN-292601
+ |
+
+
+ PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
+ configuration for an address object. If there are two address objects
+ with same FQDN, but one object has Load Balanced DNS enabled and other
+ object has Load Balanced DNS disabled, then the policy match for the
+ removed IP addresses doesn't work as expected.
+
+
+ Workaround: Enable (or disable) Load Balanced DNS
+ consistently for an FQDN that is used with multiple address objects.
+
+ |
+
|
+ PAN-290692
+ |
+
+
+ In Host Compliance Service, when you create a 'Shared' type Host
+ Compliance Object for the 'Disk-Encryption' category, the State
+ drop-down is automatically selected and cannot be edited. However, you
+ can change the state later by editing the object, if required.
+
+ |
+
|
+ PAN-289524
+ |
+
+
+ In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
+ IP addresses from a Load balanced DNS server and use them in a policy
+ match. However, this functionality does not work as intended when the
+ DNS cache reuse flag is enabled. When the DNS cache reuse flag is
+ enabled, the DNS resolution works as if the Load balanced DNS flag
+ (for an Address object) is disabled.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-283053
+
+ This issue is now resolved. See PAN-OS 12.1.5 Addressed Issues.
+
+ |
+
+
+ (PA-7000 Series with Log Forwarding Card only)
+ When the firewall is configured to forward logs to an external log
+ collector or Strata Logging Service, the firewall root partition may
+ reach high disk utilization, which can cause the firewall to become
+ non-functional. This occurs when the log collector is temporarily
+ unavailable or unable to process logs at the rate the firewall is
+ sending them.
+
+
+ Workaround: To help prevent this issue, ensure
+ network connectivity between the firewall and log collector is stable
+ and verify that the log collector has sufficient capacity to handle
+ the volume of logs generated by your deployment.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PLUG-21065
+ |
+
+
+ In a PA-VM or AI Runtime Security environment, it is observed that the
+ Software Firewall Orchestration plugin deployed with a VM-Flex license
+ and configured with 8-14 GB of memory may encounter traffic
+ disruptions when jumbo frames are enabled. It is recommended to
+ disable jumbo frames on these lower-end VMs in version 12.1.2 by
+ executing the command: set system setting jumbo-frame off.
+
+ |
+
|
+ PLUG-19238
+ |
+
+
+ Enabling Advanced Routing through bootstrap on VM-Series and Prisma
+ AIRS is not supported.
+
+ Workaround: After the firewall boots up, enable
+ advanced routing using the CLI command set device-management
+ general-settings advance-routing yes or enable
+ advanced routing
+ through the UI.
+ |
+
|
+ DRS-6556
+ |
+
+
+ For Host Compliance Service, while configuring Mappings & Tags in
+ CIE and when you click on the
+ HIP Report tab, the following error
+ message is displayed even when the response is successful:
+
+
+ getaddrinfo ENOTFOUND null
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+
|
+ PAN-317772
+ |
+
+
+ Added a fix to improve performance in lossy network conditions.
+
+ |
+
|
+ PAN-315965
+ |
+
+
+ Fixed an issue to address TCP proxy fast recovery behavior to follow
+ RFC 5681.
+
+ |
+
|
+ PAN-315919
+ |
+
+
+ Fixed an issue where GlobalProtect pre-logon tunnel session was not
+ cleared even after the user was logged in. With this fix, the session
+ is cleared after the session timeout expires.
+
+ |
+
|
+ PAN-311192
+ |
+
+
+ Fixed an issue where the
+ device-telemetry collect-now
+ process became unresponsive when the process was initiated multiple
+ times with other processes running concurrently, which prevented
+ subsequent telemetry collection.
+
+ |
+
|
+ PAN-308377
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue where the firewall reached 100% disk utilization due to
+ the
+ logrcvr
+ process repeatedly restarting and dumping core files due to a blocked
+ hints processing thread, which caused a failover.
+
+ |
+
|
+ PAN-306356
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process on a firewall stopped responding due to a document node being
+ unexpectedly freed.
+
+ |
+
|
+ PAN-303663
+ |
+
+
+ Fixed an issue on the firewall where SolarWinds monitoring systems
+ reported 100% usage for Slot1 Data Processor-0 Hardware Packet Buffers
+ due to an inaccurate reported packet buffer.
+
+ |
+
|
+ PAN-295806
+ |
+
+
+ Fixed an issue where memory leaks on the
+ configd
+ process occurred due to a hash insert operation failing during
+ connection management and SSL connections.
+
+ |
+
|
+ PAN-288175
+ |
+
+
+ Addressed a stack buffer overflow memory leak under plugin management
+ code path.
+
+ |
+
|
+ PAN-251024
+ |
+
+
+ Fixed an issue where GlobalProtect logs did not show the correct
+ region for the IP address due to content updates not retrieving the
+ latest configuration.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+
+ A fix was made to address
+ CVE-2026-0257.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ —
+ |
+
+ Fixes were made to address the following CVEs:
+
|
+